[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> FIRESIDE CHAT: Leaked secrets are now the go-to attack vector — and AI is accelerating exposures
A consequential shift is underway in how enterprise breaches begin. The leaked credential — once treated as a hygiene problem — has become the primary on-ramp. Related: No easy fixes for AI risk Last August’s Salesloft campaign was the pattern … (more…) The post FIRESIDE CHAT: Leaked secrets are no...
> Home security giant ADT data breach affects 5.5 million people
The ShinyHunters extortion group stole the personal information of 5.5 million individuals after breaching the systems of home security giant ADT earlier this month, according to data breach notification service Have I Been Pwned. [...]
> Ten Great Cybersecurity Job Opportunities
Security Boulevard is now providing a weekly cybersecurity jobs report through which opportunities for cybersecurity professionals will be highlighted as part of an effort to better serve our audience. Our goal in these challenging economic times is to make it just that much easier for cybersecurit...
> Webinar: Spotting cyberattacks before they begin
On Thursday, April 30 at 2:00 PM ET, BleepingComputer will host a live webinar with threat intelligence company Flare and threat intelligence researcher Tammy Harper, exploring how security teams can identify early warning signs of attacks before they escalate into incidents. [...]
> Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack
Checkmarx has disclosed that its ongoing investigation tied to the supply chain security incident has revealed that a cybercriminal group published data related to the company on the dark web. "Based on current evidence, we believe this data originated from Checkmarx's GitHub repository, and that ac...
> BlackFile actively extorting data-theft victims in retail and hospitality sector
Some attackers, which researchers link to The Com, have swatted company executives to increase leverage and pressure victims to pay their ransom demands. The post BlackFile actively extorting data-theft victims in retail and hospitality sector appeared first on CyberScoop.
> RansomLook : l’agrégateur open source pour surveiller les ransomwares
Threat Intelligence : RansomLook facilite le suivi et la surveillance des groupes de ransomware grâce à l'agrégation des données sur une plateforme unique. Le post RansomLook : l’agrégateur open source pour surveiller les ransomwares a été publié sur IT-Connect.
> Utilities Tech Supplier Itron Discloses Cyber-Attack, Operations Unaffected
Itron confirmed a cyber incident but does not believe it is likely to have a material impact on the company
> Short-Lived Credentials in Agentic Systems: A Practical Trade-off Guide
Understand where short-lived credentials reduce risk in agentic systems and where operational complexity requires stronger monitoring and governance controls. The post Short-Lived Credentials in Agentic Systems: A Practical Trade-off Guide appeared first on Security Boulevard.
> Medtronic confirms breach after hackers claim 9 million records theft
Medical device giant Medtronic disclosed last week that hackers breached its network and accessed data in "certain corporate IT systems." [...]
> Ubuntu 25.10 lcms2 Critical ICC Profile DoS Vulnerability USN-8209-1
Little CMS could be made to crash or run programs if it opened a specially crafted ICC profile.
> Ubuntu 25.10 Pillow Severely Affected by DoS Resource Crash Flaw USN-8211-1
Pillow could be made to crash if it opened a specially crafted file.
> Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software
A Chinese national posed as a U.S. researcher, tricking NASA staff in a phishing campaign to steal sensitive data tied to defense software and exports. A Chinese national ran a spear-phishing campaign by posing as a U.S. researcher and tricked NASA employees into sharing sensitive information. The N...
> Ubuntu 25.10 nginx Important Denial of Service Vulnerabilities USN-8210-1
Several security issues were fixed in nginx.
> Ubuntu 25.10 HAProxy Critical Info Exposure USN-8208-1 CVE-2026-33555
HAProxy could be made to expose sensitive information over the network.
> âš¡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
Everything is dumb again. This week feels broken in a very familiar way. Old tricks are back. New tools are doing shady crap. Supply chains got hit. Fake help desks worked. Weird research showed how easy some attacks still are. Most of it feels like stuff we should have fixed years ago. Bad extensio...
> Ubuntu 22.04 LTS ClamAV Critical HTML Crash DoS USN-8207-1
ClamAV could be made to crash if it opened a specially crafted HTML file.
> Ubuntu 26.04 LTS strongSwan Advisory USN-8196-2 CVE-2026-35328 to 35334
Several security issues were fixed in strongSwan.
> Widely Used Browser Extensions Selling User Data
Dozens of browser extensions openly sell user data via privacy policy disclosures
> Ubuntu 26.04 LTS PackageKit Serious Privilege Escalation Risk USN-8195-2
PackageKit could be made to install packages as the administrator.